CVE-2026-27932Disclosure(hsiaoming / joserfc)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows an unauthenticated attacker to cause a Denial of Service (DoS) via CPU exhaustion. When the library decrypts a JSON Web Encryption (JWE) token using Password-Based Encryption (PBES2) algorithms, it reads the p2c (PBES2 Count) parameter directly from the token's protected header. This parameter defines the number of iterations for the PBKDF2 key derivation function. Because joserfc does not validate or bound this value, an attacker can specify an extremely large iteration count (e.g., 2^31 - 1), forcing the server to expend massive CPU resources processing a single token. This vulnerability exists at the JWA layer and impacts all high-level JWE and JWT decryption interfaces if PBES2 algorithms are allowed by the application's policy.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • joserfc

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-03); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
joserfc

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-03: 2Mentions · 2026-03-04: 1Technical Details · 2026-03-03: 2Technical Details · 2026-03-04: 103-0303-04
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-032
Disclosure2
2026-03-041
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27932 joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustio… https://www.cve.org/CVERecord?id=CVE-2026-27932

    Post summary

    The text announces a resource exhaustion vulnerability (CVE‑2026‑27932) in the joserfc Python library, with no evidence of exploitation, PoC, or mitigation.

    01000186
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27932 Denial of Service via Unbounded PBES2 Iterations in joser... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27932 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A new CVE (CVE-2026-27932) is disclosed, describing a Denial of Service vulnerability caused by unbounded PBES2 iterations in joser, with links to vulnerability details and scanning alerts.

    0000056
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27932 joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustio… https://www.cve.org/CVERecord?id=CVE-2026-27932 ----- Traducción: CVE-2026-27932 jos… http://infoflow.cloud`

    Post summary

    CVE-2026-27932 is a resource exhaustion vulnerability in the joserfc Python library affecting versions 1.6.2 and earlier, with no PoC, exploit, or patch mentioned.

    0000031
    55 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphsiaomingjoserfc-python-

Explore more